Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Apache

2,099 known vulnerabilities

250
CRITICAL
563
HIGH
412
MEDIUM
15
LOW

Top Products

tomcat 79 airflow 70 camel 64 traffic server 64 http server 64 cxf 36 activemq 34 thrift 31 cloudstack 29 nifi 29
1,240 CVEs · Page 2/25
9.8
CVE-2026-63038

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache InLong. Thi

9.8
CVE-2026-63037

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache InLong. Thi

5.3
CVE-2026-63016

Uncontrolled Resource Consumption vulnerability in Apache InLong. Users could affect operational configuration or allow

4.3
CVE-2026-63015

Uncontrolled Resource Consumption vulnerability in Apache InLong. Non-template responsible persons can view template inf

7.5
CVE-2026-73635

Allocation of resources without limits or throttling vulnerability in Apache Struts. When no fixed locale is configured,

7.5
CVE-2026-73634

Uncontrolled resource consumption vulnerability in Apache Struts. An application that exposes an endpoint collecting Con

4.3
CVE-2026-73632

Exposure of data element to wrong session vulnerability in the JSON plugin of Apache Struts. Per-response serialization

4.3
CVE-2026-73631

Exposure of data element to wrong session vulnerability in the JSON plugin of Apache Struts. Per-request parsing state c

7.5
CVE-2026-73633

Uncontrolled resource consumption vulnerability in the JSON plugin of Apache Struts. When an application is configured t

9.8
CVE-2026-73240

Specifically crafted inputs may lead to git argument injection in Apache Allura. This issue affects Apache Allura: befo

6.5
CVE-2026-73239

Insecure Direct Object Reference (IDOR) due to missing permission checks for multiple Artifact types in Apache Allura.

6.1
CVE-2026-73238

XSS vulnerability in code display in Apache Allura. This issue affects Apache Allura: before 1.19.1. Users are recomme

6.1
CVE-2026-73237

XSS vulnerability in Markdown handling in Apache Allura. This issue affects Apache Allura: from 1.10.0 before 1.19.1.

6.5
CVE-2026-68971

Apache Airflow's asset materialization endpoint (`POST /api/v2/assets/{asset_id}/materialize`) and the XCom result check

6.5
CVE-2026-68970

Apache Airflow's Task SDK did not mask the contents of a Variable whose JSON value is a list, so secrets stored in that

6.5
CVE-2026-68969

Apache Airflow wrote Variable values and Connection `extra` contents to the audit log in cleartext when they were submit

7.5
CVE-2026-68968

Apache Airflow's Backfill API authorized a request against a Dag id supplied by the caller whenever the `backfill_id` pa

5.4
CVE-2026-68076

Apache Airflow's environment-variable secrets backend resolved a team-scoped Connection or Variable from the wrong team'

8.8
CVE-2026-67587

Apache Airflow's Task SDK rebuilt a `Callback` object from serialized data by re-running its constructor, which imports

7.3
CVE-2026-67260

Apache Airflow 3.3.0 moved human-in-the-loop tasks from the triggerer to a new `awaiting_input` task state swept by the

6.5
CVE-2026-65017

Apache Airflow's Config API did not mask team-scoped sensitive configuration values in multi-team deployments. When an a

6.5
CVE-2026-59244

Apache Airflow's secrets masker did not mask `var.json` Variable values whose value is a dict in the Rendered Templates

5.4
CVE-2026-59242

Apache Airflow's XCom `GET /api/v2/{...}/xcomEntries/{key}?deserialize=true` endpoint passed a string-literal payload th

8.8
CVE-2026-58076

Apache Airflow's serialization layer reconstructed exception nodes by calling `import_string()` on a class name taken fr

4.3
CVE-2026-54183

Apache Airflow's secrets masker hides values stored under sensitive key names when they are displayed in the UI. The mas

6.5
CVE-2026-68868

The Google Cloud Secret Manager secrets backend in Apache Airflow's Google provider never applied the team scope when re

9.1
CVE-2026-71290

Improper TLS hostname verification vulnerability in Apache HttpComponents Client 5.4 or newer. HostnameVerificationPolic

9.1
CVE-2026-69223

Apache Allura's webhooks are vulnerable to Server-Side Request Forgery (SSRF). This issue affects Apache Allura: before

6.5
CVE-2026-68872

The AWS Systems Manager Parameter Store and Secrets Manager backends in Apache Airflow's Amazon provider resolved a team

6.5
CVE-2026-68871

The Yandex Lockbox secrets backend in Apache Airflow's Yandex provider resolved a team-scoped Connection or Variable id

7.3
CVE-2026-65948

UnixAuth lacks brute-force protection in Apache Ranger versions <= 2.8.0.  Note:  UnixAuth is NOT a recommended option f

6.5
CVE-2026-65945

Logs contain replayable JWT tokens in Apache Ranger versions <= 2.8.0 Users are recommended to upgrade to version 2.9.0,

7.5
CVE-2026-65942

TLS hostname verification issue in Apache Ranger Client Code in versions <= 2.8.0. Users are recommended to upgrade to v

7.5
CVE-2026-61899

Vulnerability in tapestry-core in Apache Tapestry 5.5.0+ on all platforms allows attackers to download clsspath assets v

7.5
CVE-2026-55814

Missing Authentication in Apache Ranger Download APIs on versions <= 2.8.0. Users are recommended to upgrade to version

9.8
CVE-2026-55799

Remote Code Execution Vulnerability in GraalScriptEngineCreator in Apache Ranger <= 2.8.0 Users are recommended to upgra

9.8
CVE-2026-44416

Remote Code Execution via Arbitrary Class Instantiation in plugin-schema-registry component in Apache Ranger <= 2.8.0. U

9.8
CVE-2026-42537

Remote Code Execution via JDBC URL Injection in Apache Ranger <= 2.8.0 Users are recommended to upgrade to version 2.9.0

9.8
CVE-2026-40920

Privilege Escalation via URL Parameter is reported in Apache Ranger versions <= 2.8.0. Users are recommended to upgrade

9.8
CVE-2026-32227

SQL Injection vulnerability vulnerability in Apache Ranger. This issue affects . Users are recommended to upgrade to v

9.8
CVE-2026-28672

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Ranger. Thi

9.1
CVE-2026-71560

Out-of-bounds Read vulnerability in Apache Fory C++ deserialization. This issue affects Apache Fory C++ versions from 0

7.5
CVE-2026-71559

Deserialization of Untrusted Data vulnerability in the Go implementation of Apache Fory allows an attacker to cause a de

9.8
CVE-2026-71558

Heap type confusion vulnerability in Apache Fory C++ deserialization. This issue affects Apache Fory C++ versions from

7.5
CVE-2026-34502

Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility memcached client This issue affects Apache

7.5
CVE-2026-34501

Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility redis client. This issue affects Apache Por

9.1
CVE-2026-34191

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Portable Ru

9.1
CVE-2026-32327

A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library consumer which parses

7.5
CVE-2025-49506

APR-util versions 1.6.3 (and earlier) function apr_password_validate() was not constant-time with regards to hashes or p

7.5
CVE-2026-68481

In Apache CXF's DefaultEncryptingOAuthDataProvider, revoked access tokens still decrypt successfully, and TokenIntrospec

Frequently Asked Questions

How many CVEs affect Apache?

Apache has 2,099 CVE records in our database, including 281 critical and 645 high severity vulnerabilities. 14 of these are listed in CISA's Known Exploited Vulnerabilities catalog.

What are the most severe Apache vulnerabilities?

Apache has 281 critical severity (CVSS 9.0+) and 645 high severity (CVSS 7.0-8.9) vulnerabilities. 14 vulnerabilities are confirmed as actively exploited in the wild.

How can I scan for Apache vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Apache products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Apache Vulnerabilities

CyberStrike scans your infrastructure for Apache vulnerabilities and provides real-time remediation guidance.

Get Started